diff --git a/advisories/github-reviewed/2024/10/GHSA-j945-c44v-97g6/GHSA-j945-c44v-97g6.json b/advisories/github-reviewed/2024/10/GHSA-j945-c44v-97g6/GHSA-j945-c44v-97g6.json new file mode 100644 index 00000000000..d567728495f --- /dev/null +++ b/advisories/github-reviewed/2024/10/GHSA-j945-c44v-97g6/GHSA-j945-c44v-97g6.json @@ -0,0 +1,179 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j945-c44v-97g6", + "modified": "2024-10-28T18:30:32Z", + "published": "2024-10-28T18:30:32Z", + "aliases": [ + "CVE-2024-49771" + ], + "summary": "MPXJ has a Potential Path Traversal Vulnerability", + "details": "### Impact\nThe patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations.\n\n### Patches\nThe issue is addressed in MPXJ version 13.5.1\n\n### Workarounds\nDo not pass zip files to MPXJ.\n\n### References\nN/A\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "net.sf.mpxj:mpxj" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "RubyGems", + "name": "mpxj" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "mpxj" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "net.sf.mpxj" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "net.sf.mpxj-for-csharp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "net.sf.mpxj-for-vb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.3.5" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "MPXJ.Net" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + }, + { + "fixed": "13.5.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/joniles/mpxj/security/advisories/GHSA-j945-c44v-97g6" + }, + { + "type": "WEB", + "url": "https://github.com/joniles/mpxj/commit/8002802890dfdc8bc74259f37e053e15b827eea0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/joniles/mpxj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-10-28T18:30:32Z", + "nvd_published_at": null + } +} \ No newline at end of file